How we research and compare penetration testing offers

Updated

This page explains how the current comparison was built: which offers are included, how evidence is recorded, how prices and terms are made comparable, how Purchase Checks reach a finding, and how corrections work. The full comparison was checked on ; specific terms were rechecked on .

By The PenTest Index

This site may contain affiliate or referral links. If you buy through one, we may be compensated. Read how we make money.

The current sample

The comparison covers selected offers from 8 companies: 12 managed testing entries and 3 scanning tools, supported by 15 provider source pages.

Every entry in the current sample:

  • is a specific offer described on the provider’s own website;
  • covers web application or API testing, or is a scanning tool a buyer may consider alongside a test; and
  • has a public page describing its scope and at least one of its price basis, retest terms or timing.

These are properties every current entry shares, not a claim of completeness. The sample is not a census of the market, being included is not an endorsement, and payment plays no part in inclusion.

What one entry represents

Each entry is a specific offer, not a company. One company can sell human testing, AI testing and scanning as separate products, and one entry can contain several packages, such as tiers or black-box and gray-box versions. Facts are recorded against the package they apply to.

Grouping and order

Managed testing offers are grouped by who leads the testing:

  • Tests led by people: human testers carry out the testing.
  • Tests led by AI: an AI system performs much of the testing, with a human role that differs from offer to offer.

Scanning tools you operate yourself are shown separately. Within each group, companies are listed A to Z, and a company with more than one entry keeps its entries together. Nothing is ranked, scored or rated.

Source observations

Every fact comes from a source observation, which records:

  • the exact offer and package;
  • the source page, and the section of it that states the fact;
  • the date that fact was checked;
  • the type of evidence;
  • what the fact applies to, such as a single package or plan; and
  • any limitation or conflict.
Evidence typeMeaning
Provider-publishedThe provider’s own public page states this. It is not an assessment of testing quality.
Confirmed in writingThe provider confirmed this in writing. It applies only to the recipient and brief named.
Sample inspectedWe inspected a sample deliverable. It supports only what the sample shows.
Buyer-reportedA buyer reported this. It describes one purchase, not every purchase.
Documented purchase outcomeA documented purchase shows this outcome for that purchase.

All reported offer facts in the current comparison are provider-published. The other types are recorded only when that evidence exists, and each supports only what was actually checked. These labels identify the evidence; they are not a service-quality score or a certification of a company. Our calculations and Purchase Check findings are derived analysis, shown separately from source observations.

Applicable evidence

A fact is used only where it applies. Before a fact supports a comparison cell or a finding, it must concern the same offer and package, the same kind of buyer, the same period, the same scope and the same billing basis. A term stated for one package is not carried over to another.

Dates

Each fact carries the date it was checked, and pages show when the comparison was checked, never when the site was built. Four dates have separate meanings: when a source was checked, when a finding was produced, when a page was last meaningfully edited and when that page was first published. A partial recheck changes only the dates for the facts rechecked; it does not refresh the entire comparison.

Prices and commitments

  • Prices are in US dollars for the stated package and unit, such as per test, per target or per year.
  • The kind of price is kept: a fixed advertised price, a starting price, a promotion, a price set by the provider’s plan calculator, or quote required. Quoted, contracted and paid prices would be labeled as such; the current comparison contains none.
  • Starting-price conditions and required additions, such as a separate platform charge, stay beside the price.
  • An annual price stays annual. It is not converted into a monthly figure, and a minimum term is shown as stated.
  • An unknown fee stays unknown. It is never treated as zero, so no total is given while a required cost is missing.
  • A promotional price is shown only with its conditions and expiry, and an expired promotion is never shown as a current price.

Retesting and timing

Retest terms are recorded in parts: how many retests are included, what starts the window, whether the deadline applies to requesting the retest or to completing it, the human role, and any exclusions or contract cutoff.

Timing keeps the stages of a project apart: booking or start, active testing, the assessment window, first findings, the final report and retesting. A provider’s statement about one stage is not used for another.

Unknowns and conflicts

“Not stated” means the detail was not found in the sources reviewed. It is never read as a “no” or as zero.

When two of a provider’s own sources disagree about the same applicable term, both statements are shown, and the next step is to ask the provider for the applicable term in writing. We do not silently resolve a disagreement by choosing the more attractive term. The current comparison identifies conflicting statements about Cobalt’s unused Enterprise credits and differing published estimates for Astra’s manual testing duration. The comparison names the sources and the estimate shown; the provider must confirm the terms for the buyer’s agreement.

Purchase Checks

A Purchase Check tests one condition of an example purchase against one offer’s published terms. Every check follows the same sequence:

  1. Requirement. One condition from the brief, recorded as mandatory, preferred or assumed.
  2. Applicable evidence. The observations that apply to that offer, package and condition.
  3. Rule or calculation. A small, fixed rule, or arithmetic on published figures.
  4. Finding. One of five states, with the reason.
  5. Next question. What is still open, written as a question for the provider.
  6. Revision condition. The evidence that would change the finding.

Each finding records the offer, brief and rule it used, the source observations and their check dates, its inputs, the date it was produced and its review status.

The five states

StateMeaning
SupportedApplicable evidence satisfies the stated condition, within the limits named in the finding.
MismatchApplicable evidence contradicts a mandatory condition of the brief.
UnresolvedThe evidence needed for a decision is missing, incomplete or not yet applicable to the buyer.
ConflictingSources disagree about the same applicable condition after checking offer, audience, date, scope and billing basis.
Not applicableThe condition does not arise for this brief or offer.

Brief W1

The current checks use brief W1, version 1.0. It describes an illustrative purchase, not a real buyer’s request, and no provider has quoted for it.

Brief W1 version 1.0 conditions
ConditionStatus
One SaaS web application and the API it consumesmandatory
Two authenticated user rolesmandatory
One agreed testing environmentassumed
No source code accessmandatory
One managed assessmentassumed
Manual check of fixes requested 45 days after findings are reportedmandatory
A complete, itemized purchase commitmentmandatory

The four worked checks

These are the checks shown on the homepage, with the rule and inputs behind each finding.

The four worked Purchase Checks against brief W1.
Purchase conditionWhat the published terms establishQuestion to send the provider
Two authenticated user rolesMandatory in the brief

Supported · starting amount only

Pentest-Tools.com gray box: $5,200 starting amount, calculated as $3,400 + (2 × $900). The complete price for the API, retesting and any additional scope is unresolved. Published formula (Pentest-Tools.com source: Managed web app testing)

“For this app, its API and two roles, what is the complete price, including a manual retest requested 45 days after findings are reported?”

Rule and provenance: Two authenticated user roles, Pentest-Tools.com · Managed web app testing
Offer evaluated
Pentest-Tools.com · Managed web app testing — Gray box. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Two authenticated user roles (mandatory). Managed gray-box web app test as published; two authenticated user roles; no other scope priced.
Evidence applied
  • Price · Provider-published · Managed web app testing (Pentest-Tools.com source), Grey box web app pentest, price section. Lists manual testing that includes authenticated user roles, starting at {{usd:pentest-tools-gray-box.price.amount}} plus {{usd:pentest-tools-gray-box.price.perUserRole}} per user role, with four or more working days of testing and the report when ready. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Published starting base + role count × published role charge (rule version 1.0)
Inputs read
  • Base amount: $3,400
  • Per role amount: $900
  • Roles: 2
  • Price status: starting
Result
Supported. The published formula gives a conditional starting amount for 2 authenticated roles. It does not price API coverage, complexity, required additions or retesting, so the whole-brief price remains unresolved. Amount: $5,200 (Conditional starting amount for 2 authenticated roles; not a quote or complete price).
Still open
  • API coverage, complexity and any required additions
  • A manual retest requested on day 45
  • Delivery dates
What would change it
A confirmed scope and itemized quote can change the whole-brief price finding. Losing the published formula removes this Supported finding.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-01 · Purchase Check method 1.0
Manual retest requested on day 45Mandatory in the brief

Mismatch · included request window

Astra Expert: outside the included request window. Its two manual re-scans must be requested within 30 days of findings being reported. Extensions are considered case by case. Rescan terms (Astra source: Rescan rules)

“Can you include a manual re-scan requested 45 days after findings are reported? Please confirm the extension and any added cost in writing.”

Rule and provenance: Manual retest requested on day 45, Astra · Pentest Expert
Offer evaluated
Astra · Pentest Expert. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Manual retest requested on day 45 (mandatory). Pentest Expert’s included manual re-scans; the window limits the request and runs from reported findings.
Evidence applied
  • Retesting · Provider-published · Rescan rules (Astra source), Rescan Validity Period, Expert row. Allows {{words:astra-pentest-expert.retest.count}} manual re-scans, requested within {{num:astra-pentest-expert.retest.windowDays}} days of findings being reported. Extensions are considered case by case. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Requested day compared with the published retest window and what it limits (rule version 1.0)
Inputs read
  • Request day: 45
  • Window days: 30
  • Deadline applies: request
  • Window trigger: findings being reported
  • Included count: 2
  • Manual: yes
Result
Mismatch. A request on day 45 falls outside the published 30-day window, which runs from findings being reported.
Still open
  • Whether Astra will extend the request window, and at what price
What would change it
A written extension can resolve this condition; its price is not assumed. A request made within the window changes the timing check only.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-02 · Purchase Check method 1.0
No source code accessMandatory in the brief

Mismatch · source code access

Intruder’s listed offer: access mismatch. Its white-box workflow requires connecting a code repository. A different arrangement would need confirmation. Offer and workflow (Intruder source: Pentest pricing)

“Do you offer a test without access to our source code? Please confirm its scope, testing approach and price.”

Rule and provenance: No source code access, Intruder · AI web app pentest
Offer evaluated
Intruder · AI web app pentest. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: No source code access (mandatory). Intruder’s listed AI web app pentest and its connect-codebase workflow.
Evidence applied
  • Access required · Provider-published · Pentest pricing (Intruder source), Repository integration and connect-codebase step. Describes AI-powered white-box web app testing whose workflow requires connecting a code repository. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Required repository access compared with the buyer’s access constraint (rule version 1.0)
Inputs read
  • Buyer provides source code: no
  • Repository required: yes
Result
Mismatch. The offer’s workflow requires connecting a code repository; the brief rules out source code access.
Still open
  • Whether Intruder offers an evidenced alternative without repository access
What would change it
An evidenced alternative offer or a buyer-authorized change to the constraint can change this result only.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-03 · Purchase Check method 1.0
Complete purchase commitmentMandatory in the brief

Unresolved · complete total

SynackST: total unresolved. The test starts at $10,283; a platform line item is required, and a free Basic tier is also described. Which tier applies still needs confirming. Platform and test terms (Synack source: Testing packages, platform terms and credit expiry FAQ)

“Can SynackST cover this app and API, and is the Basic platform tier eligible? Please itemize the test, any required platform charge, when purchased credits expire and the full contractual commitment.”

Rule and provenance: Complete purchase commitment, Synack · SynackST
Offer evaluated
Synack · SynackST. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Complete purchase commitment (mandatory). SynackST as published: a starting test component plus a required platform line item.
Evidence applied
  • Price · Provider-published · Testing packages, platform terms and credit expiry FAQ (Synack source), Testing packages, SynackST. Lists SynackST from {{usd:synack-st.price.amount}} per test: one human tester; up to 25 unauthenticated web apps, one low-complexity authenticated app, or 100 host IPs; a five-day assessment window; patch verification listed. Checked October 7, 2026; rechecked October 8, 2026.
  • Platform · Provider-published · Testing packages, platform terms and credit expiry FAQ (Synack source), Pricing table note and platform tier descriptions. States that a platform line item is required in addition to the test, and describes a free Basic platform tier. Checked October 7, 2026; rechecked October 8, 2026.
Rule
Sum of current required components; unknown required charges make the total incomplete (rule version 1.0)
Inputs read
  • Base amount: $10,283
  • Base status: starting
  • Promotion expired: no
  • Required additions: 1
  • Unknown required additions: 1
Result
Unresolved. A required component has no applicable published charge. An unknown required charge is not treated as zero, so the complete total cannot be calculated.
Still open
  • Whether the free Basic platform tier is eligible
  • The required platform charge
  • How the published one-year credit expiry applies to this purchase
  • An itemized, complete commitment
What would change it
Itemized written confirmation of the test, the applicable platform tier and its charge. Other fit checks remain.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-04 · Purchase Check method 1.0

Two further examples

The worked checks reach Supported, Mismatch and Unresolved findings. These two examples show the other two states.

Two further checks that illustrate the Conflicting and Not applicable states.
Purchase conditionWhat the published terms establishQuestion to send the provider
Unused-credit terms for an annual credit packageMandatory in the brief

Conflicting · credit rollover

Cobalt Enterprise: rollover terms conflict. The Enterprise comparison table lists rollover of up to 10%; the pricing FAQ says credits do not roll into the next contract. Compare both statements (Cobalt source: Pricing and offer terms, including conflicting rollover statements)

“Which unused-credit term will apply to our Enterprise agreement? Please confirm it in writing.”

Rule and provenance: Unused-credit terms for an annual credit package, Cobalt · Standard / Premium / Enterprise
Offer evaluated
Cobalt · Standard / Premium / Enterprise — Enterprise. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Unused-credit terms for an annual credit package (mandatory). Cobalt Enterprise; two statements on the same pricing page.
Evidence applied
Rule
Applicable sources must agree about the same condition (rule version 1.0)
Inputs read
  • Applicable evidence: 3
  • Conflicting: 2
Result
Conflicting. Statements from the same provider disagree about this condition; written clarification is needed.
Still open
  • Which rollover term applies to the buyer’s agreement
What would change it
Written confirmation from Cobalt, or a published correction that removes one statement.
Dates
Sources checked October 7, 2026 and October 8, 2026. Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-M1 · Purchase Check method 1.0
Tester location or on-site workAssumed in the brief

Not applicable · tester location

Tester location: not applicable to this brief. W1 includes no on-site work or contractual location restriction, so the check does not arise.

“If your contract restricts tester location or data handling, add it to your brief and ask every provider the same question.”

Rule and provenance: Tester location or on-site work, Synack · SynackST
Offer evaluated
Synack · SynackST. Terms as checked October 8, 2026.
Brief and condition
Illustrative brief W1, version 1.0: Tester location or on-site work (assumed). Brief W1, which has no on-site or tester-location requirement.
Evidence applied
None needed: the brief does not include this condition.
Rule
A condition is assessed only when the brief includes it (rule version 1.0)
Inputs read
  • On site work required: no
Result
Not applicable. The brief has no on-site or tester-location requirement, so tester location is not assessed.
What would change it
A brief that requires on-site work or restricts tester location.
Dates
Finding produced October 8, 2026.
Review status
Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.
Record
PC-W1-M2 · Purchase Check method 1.0

Rules that protect findings

  • If supporting evidence is removed or stops applying, a Supported finding is withdrawn.
  • If a required cost is unknown, no total price is given.
  • An expired promotion cannot be used as a current price.
  • Payment is never an input to any rule.
  • Each finding’s state and any amount are recomputed by automated tests. If a source change alters the result, the content checks fail until the finding is reviewed.

Review status

Arithmetic and rule outputs are reproduced by automated tests. No competent technical review of these findings has been recorded.

Corrections and updates

Each fact is stored once and reused wherever it appears. When a source changes:

  1. the observation is updated with the new statement, section and check date;
  2. every comparison cell and finding that depends on it is rechecked, and the content checks fail until each changed finding is resolved; and
  3. the affected pages show the new check date.

A change to a fact, price, finding or date is a material update and is listed below with its date. Spelling and layout fixes are not listed.

Material updates

DateUpdate
October 7, 2026Full comparison checked against provider sources.
October 8, 2026Purchase Check sources rechecked, with Cobalt’s start-time and rollover terms and Synack’s credit-expiry terms.
October 8, 2026Targeted Intruder price recheck: its pricing page lists $4,000 per test and $3,500 for platform subscribers. The subscriber condition is retained beside the price; the page itself publishes both amounts.

This record documents the source checks above. A material factual correction or later change to provider terms is added here when published, with the affected information identified. A later provider change is distinguished from a correction to our earlier reporting.

To report an error, follow the correction steps on the contact page. The editorial standards explain how corrections are decided.

Maintenance

  • Monthly review schedule: recheck every provider source and the records that depend on it. A check date changes only for facts that were actually rechecked. The dates beside the facts show completed work, not a promise that a scheduled check has already happened.
  • Promotions and limited-time terms: checked against their stated expiry and removed when they lapse.
  • Reported changes: a correction or a provider update triggers a recheck of the affected source and everything that depends on it.

Guidance and its limits

Our purchasing approach draws on CREST’s penetration testing procurement guidance, particularly specifying requirements and selecting suitable suppliers, and NIST SP 800-115, which addresses planning, conducting and analyzing technical security assessments. The scope checklist identifies the passages consulted for its questions.

These documents inform the questions we ask. They do not endorse this publication, validate the listed providers or establish that an offer meets a current contractual or regulatory requirement. A claim about a requirement must cite the applicable current requirement, not rely on a general or older guidance document.

Citing a finding

Attribute our calculations and applied findings to The PenTest Index, link to the page or specific finding, and preserve the offer, brief, check date and limits that affect the conclusion. Attribute provider terms to the provider’s cited source. A worked starting amount must not be described as a collected quote or complete project price. See the terms of use for reuse.

Find My PenTest Match